Thank you so much for this video, I have been struggling with sophos ( we are just starting to use them at work ) this has made my day / week / month. Thank you so much.
@MikeFaucher2 жыл бұрын
Glad to hear that. Powerful but long learning curve. Best of luck.
@fat-Steve Жыл бұрын
Thaks for making this Mike. My understanding of what was going on just needed this video to tie it all together.
@MikeFaucher Жыл бұрын
Glad to hear it helped.
@Shrav21125 жыл бұрын
I rarely comment but I had to say "thanks" for this vid. It stopped me banging my head against a wall and got my VLANs all sorted out now!
@MikeFaucher5 жыл бұрын
Glad it helped. Thanks for commenting.
@jeffmacdougall91902 жыл бұрын
This was very helpful. I have to take this to the next level. I have a Main Office with 2 branch locations connect to Main via Site-2-Site. Main Avaya VoIP system is in Main Office and I need to setup VLAN for all phones at all locations.
@MikeFaucher2 жыл бұрын
Glad i was help. For future reference, Sophos V19 has enhanced the site to site capability. Good luck and thanks for the feedback.
@MikeFaucher5 жыл бұрын
I know some of you have sent questions. I am out of the country for two weeks and will respond when I get back. Thank you.
@MAbdilahi6 жыл бұрын
thanks, i can't wait to see the next video wireless that connected to VLAN.
@MikeFaucher6 жыл бұрын
Thanks for the comment. WIll have something in the next week or two.
@GorkemYildirim3 жыл бұрын
Great detailed information. Thanks a lot.
@MikeFaucher3 жыл бұрын
Glad it was helpful!
@GorkemYildirim3 жыл бұрын
@@MikeFaucher your sophos xg videos thought me a lot indeed.
@danimoosakhan5 жыл бұрын
So after creating vlan on physical port, don't we have to trunk the port on the switch as well? I wonder how else the vlan is communicating across the switch. For example, if you have multiple vlans on single physical port on router, you would trunk the port on switch and create the vlans with the same vlan IDs on switch as well.
@MikeFaucher5 жыл бұрын
You are right and I actually did a separate video on the switch configuration. kzbin.info/www/bejne/jpTJZGCnbaZkl6c. Thanks for pointing this out.
@canadianwildlifeservice8883 Жыл бұрын
Can you explain the need for the MASQ NAT rule? I don't quite understand what it does.
@MikeFaucher Жыл бұрын
It is really just a SNAT and translates an external request to an internal device. It is used for things like port forwarding to route the external IP/Port to an internal IP.. Hope that helps.
@bimbsky20002 жыл бұрын
you have assigned 2 vlans in port no.3 right? so what is the configuration in the switch? is that work with cisco trunk?
@MikeFaucher2 жыл бұрын
Have not used Cisco swithches but here is a different video. Things have changed a bit but this will better show how I configured it,
@r.mega.3 жыл бұрын
Thank you for video!
@MikeFaucher3 жыл бұрын
Glad you found it useful.
@ShairKhan-jx3rl Жыл бұрын
Awesome 👌
@MikeFaucher Жыл бұрын
Thank you for the feedback!
@nanakwadjo22606 жыл бұрын
Thanks for this video. Good job
@wallywoll73346 жыл бұрын
Mike would you have any experience configuring VoIP phones within Sophos xg, preferred with a vlan. ALSO QOS Applied.
@SKfareed1233 жыл бұрын
We have to create VLAN in switch also to communicate.
@MikeFaucher3 жыл бұрын
Good feedback, Thanks.
@amitsharma-rm3ir4 жыл бұрын
Hi Mike, Configuring IP addres for vlan is a feature of L3 Switch where we named it as SVI.....Then why do we need to configure it in firewall.....it's little confusing me.... however you taught very well....I understood everything what you said....but SVI in firewall why is it??
@MikeFaucher4 жыл бұрын
Good question. You actually only need in one or the other not both. Which you use depends on the equipment you have. Since I do not have a layer 3 switch, I used interfaces. Great point.
@amitsharma-rm3ir4 жыл бұрын
@@MikeFaucher so in this case...over the layer 2 switche we make same id of vlans???
@MikeFaucher4 жыл бұрын
@@amitsharma-rm3ir You can do it over VLAN interfaces in the router.
@mohamedboukredia42254 жыл бұрын
Hello @@MikeFaucher can you please give me more informations on how to connect sophos xg with cisco switch after creating Vlans..i mean , i have to use trunk port or acces ?and i thnk i have to create vlan also on cisco switch te performe communication.
@renjithknair77245 жыл бұрын
sir how to create inter vlan routing between two vlan and how make trunk port to sent traffic to another switch?
@MikeFaucher5 жыл бұрын
RENJITH K NAIR By definition, the VLANs are isolated from each other. You can create a firewall rule that allows certain devices to talk with one another if you require that but under a normal VLAN configuration they only communicate with the WAN. If you allow full communication between two VLANS it mostly defeats the isolation.
@williamnichols71124 жыл бұрын
Hi Mike, I really enjoyed your video, well done and easy to understand. I want to do this for a "security Camera" network, but would like to have people be able to access the NVR's on the VLAN from the LAN. Is that simply just adding a Firewall rule to allow the VLAN to see the LAN like you did for the WAN? Thanks again for a well done video.
@MikeFaucher4 жыл бұрын
You probably do want to add a specific rule that allows access only to the NVR, not the entire VLAN. Another word to "allow" the LAN to access the NVR IP address.
@williamnichols71124 жыл бұрын
@@MikeFaucher Thank you sir. I look forward to learning more from you.
@samueladuamah-yeboah81793 жыл бұрын
Hi mike this is Exact video i was looking for because i want two networks setup Residential and Office and i want these networks on different firewall rules. Also i want to setup one more Vlan for Nvr use without internet is that possible?
@MikeFaucher3 жыл бұрын
Absolutely. The process is exactly the same except select deny when creating a firewall rule for that NVR VLAN. Hope that helps.
@samueladuamah-yeboah81793 жыл бұрын
@@MikeFaucher Thanks for this advice cheers
@christian45534 жыл бұрын
Hello Mike, this video was really helpful, it helped put me in the right direction on what i want to achieve as regards vlans and UniFi APs. having a little trouble though after all is done and client/hosts connects to the wireless network created with the vlan! DHCP wont lease IPs, they get a strange IP not mentioned in the whole config. any help on how to troubleshoot this will be appreciated.
@MikeFaucher4 жыл бұрын
I am not 100% sure what you are seeing in terms of IP address. The biggest issue I have seen with VLANs is making sure that are setup from start to finish. Specifically, starting from the AP, you need to define a separate WiFI network and it should be set to use the VLAN ID that you want to use. From there, your switch has to be a managed switch or VLAN aware and lastly, your router has to have the DHCP and interface that is dedicated to the that VLAN. It really sounds like there is no DHCP that has been setup. Unify AP are easy to setup with wireless networks but they rely on your router/gateway for DHCP. If you are using Sophos, make sure that you have a dedicated DHCP for the VLAN. Not sure if that helped but let me know.
@christian45534 жыл бұрын
@@MikeFaucher Thanks for you quick response, it is very appreciated. i did define a separate WiFi Network and set it to use the VLAN ID that i want it to use, also my switch is a manage switch and VLAN aware as i have a couple of those on there as well. i am using Sophos and UniFi AP Pros so it was a complete verbatim replication from you two videos. created the VLAN interface on my sophos under my LAN interface, created a DHCP and assigned it the VLAN interface with the IP lease range, created IP range under host and services, finish up with a firewall rule and then move over to UniFi Controller and created a new WiFi Network with VLAN ID created earlier. but when clients connect, they don't get assigned the IP range specified in my DHCP and so no internet. dont know whats going wrong
@MikeFaucher4 жыл бұрын
@@christian4553 Interesting sounds like you did everything right but something is off if you are not getting the IP range. I assume your devices do not connect to the internet? What range of IP did you expect and what are you getting? I am assuming your switch is set to pass through VLAN traffic? It truly sounds like your devices are not getting to the DHCP server and are being blocked by your switch. Hard to be exact without seeing your exact configuration.
@michaelroberts1516 жыл бұрын
Hi Mike, Thanks for the video. I was wondering why you defined IOT as a range (the whole range) and not just defined it as /24 network? Thanks, Mike
@MikeFaucher6 жыл бұрын
You can do either but I had more predictable behavior when I defined the range. Certainly interested if you get different results. Thanks for the comment.
@christiankimangeles94685 жыл бұрын
Do you have a a video on how to connect Unifi AC Pro to Sophos XG?
@MikeFaucher5 жыл бұрын
Not directly but I can something to my list for future consideration. Is the what you are looking more on AC Pro or configuring a dedicated port for AP on Sophos? It will help me if you expand on your question. Thanks for the comment.
@christiankimangeles94685 жыл бұрын
@@MikeFaucher we have an existing network, so if possible I would like to create a VLAN on my current LAN and use the VLAN on may AC Pro, btw i dont have USG
@MikeFaucher5 жыл бұрын
Thanks for the explanation. Have you seen this one yet: kzbin.info/www/bejne/jpTJZGCnbaZkl6c
@johnmax25035 жыл бұрын
Hi ,Can u be in port one to recieve the tag aswell ,or must u be plugged into poert 3 where its binned.
@MikeFaucher5 жыл бұрын
If I understand the question, you can attach the VLAN to any LAN port that you are using so if you have your internal LAN on Port 1, you can and should create VLAN to that port. You have to attach VLANs to the same port you LAN is on. I hope that helps and thanks for the question.
@renjiithknair88695 жыл бұрын
Also your 3rd port is reserved for second network. So how it is possible to create the vlan on same port number 3??
@MikeFaucher5 жыл бұрын
RENJIITH K NAIR Good question. VLANs have to be bound to any physical LAN port so you can create VLANs that are either or both LAN ports, Though it makes things a bit confusing, depending on the physical wiring, I can have a VLAN on one network and a different VLAN completely separate on a different port/network. For clarity, it is always easier to have on physical network and multiple VLANS on that same network. That would be more versatile.
@renjiithknair88695 жыл бұрын
@@MikeFaucher sir also one of the qnap training video .. am waiting for that...how to secure qnap nas..
@MikeFaucher5 жыл бұрын
@@renjiithknair8869 I will add it to my list. Thanks for the suggestion.
@JamesRossBowles6 жыл бұрын
Love the video, but its possibly named wrong. This was very helpful and could possibly help a lot more people, as the Sophos video tutorials are sparse.
@MikeFaucher6 жыл бұрын
Thanks for the feedback and pointing out my naming issue. I appreciate you telling Did not catch that. Thanks again.
@sahilhussain36475 жыл бұрын
Hi sir, your video is very good.i just want know how we can make the communication between that vlan(iot) to Port 1 and Port 1 to vlan( iot)